security Archives - Developer Tech News https://www.developer-tech.com/news/tag/security/ Gaming, Apps, HTML5, Java, PHP, C#, .net, IOT Mon, 04 Nov 2024 15:26:39 +0000 en-GB hourly 1 https://www.developer-tech.com/wp-content/uploads/2020/09/dev-icon-60x60.png security Archives - Developer Tech News https://www.developer-tech.com/news/tag/security/ 32 32 NPM supply chain attack uses Ethereum blockchain https://www.developer-tech.com/news/npm-supply-chain-attack-ethereum-blockchain/ https://www.developer-tech.com/news/npm-supply-chain-attack-ethereum-blockchain/#respond Mon, 04 Nov 2024 15:26:36 +0000 https://www.developer-tech.com/?p=46773 Checkmarx researchers have detected a unique supply chain attack within the NPM ecosystem that uses the Ethereum blockchain. The malicious package, dubbed “jest-fet-mock,” targets developers with a multi-platform malware employing Ethereum smart contracts for command-and-control (C2) operations. This marks a convergence of blockchain technology with traditional attack vectors—a method not yet observed in NPM packages. ... Read more »

The post NPM supply chain attack uses Ethereum blockchain appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/npm-supply-chain-attack-ethereum-blockchain/feed/ 0
EMERALDWHALE exploits vulnerable Git configuration files https://www.developer-tech.com/news/emeraldwhale-exploits-vulnerable-git-configuration-files/ https://www.developer-tech.com/news/emeraldwhale-exploits-vulnerable-git-configuration-files/#respond Fri, 01 Nov 2024 15:35:46 +0000 https://www.developer-tech.com/?p=46764 Sysdig’s Threat Research Team (TRT) has uncovered a global operation known as EMERALDWHALE, which has stolen over 15,000 cloud service credentials by exploiting exposed Git configuration files. EMERALDWHALE utilised multiple private tools to exploit several misconfigured web services, resulting in the theft of credentials from more than 10,000 private repositories. Though the operation’s primary targets... Read more »

The post EMERALDWHALE exploits vulnerable Git configuration files appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/emeraldwhale-exploits-vulnerable-git-configuration-files/feed/ 0
Foundem vs. Google: How one startup’s story shaped big tech regulations https://www.developer-tech.com/news/foundem-vs-google-how-one-startups-story-shaped-big-tech-regulations/ https://www.developer-tech.com/news/foundem-vs-google-how-one-startups-story-shaped-big-tech-regulations/#respond Thu, 31 Oct 2024 08:00:54 +0000 https://www.developer-tech.com/?p=46737 For most startup founders, launch day is a nerve-wracking blend of excitement and worry. But for Shivaun Raff and her husband, Adam, that day in June 2006 turned into a nightmare they hadn’t seen coming. Their new venture, Foundem—a unique price comparison website they’d left stable careers to create—was finally live. But soon after launch,... Read more »

The post Foundem vs. Google: How one startup’s story shaped big tech regulations appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/foundem-vs-google-how-one-startups-story-shaped-big-tech-regulations/feed/ 0
Beyond antivirus: Other essential tools to protect your Mac https://www.developer-tech.com/news/beyond-antivirus-other-essential-tools-to-protect-your-mac/ https://www.developer-tech.com/news/beyond-antivirus-other-essential-tools-to-protect-your-mac/#respond Thu, 31 Oct 2024 08:00:50 +0000 https://www.developer-tech.com/?p=46749 Macs were once thought to be nearly invincible from a cybersecurity perspective, but now face more threats than ever. Just a few years ago, Mac-specific malware was a rarity. In 2021, security specialist Patrick Wardle discovered eight new malware families that targeted the platform. By 2023, that number grew to 21. While this may seem... Read more »

The post Beyond antivirus: Other essential tools to protect your Mac appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/beyond-antivirus-other-essential-tools-to-protect-your-mac/feed/ 0
Holistic’s open-source tools counter AI development risks https://www.developer-tech.com/news/holistic-open-source-tools-counter-ai-development-risks/ https://www.developer-tech.com/news/holistic-open-source-tools-counter-ai-development-risks/#respond Wed, 23 Oct 2024 09:27:35 +0000 https://www.developer-tech.com/?p=46715 Holistic has unveiled an open-source library to help counter AI development risks and build fairer and more responsible systems. The library – dubbed Holistic AI OSL – arrives at a crucial moment when organisations are increasingly deploying AI systems across sensitive domains including recruitment, healthcare, and financial services. Recent studies suggest that 65% of AI... Read more »

The post Holistic’s open-source tools counter AI development risks appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/holistic-open-source-tools-counter-ai-development-risks/feed/ 0
Zscaler highlights security trends challenging developers https://www.developer-tech.com/news/zscaler-security-trends-challenging-developers/ https://www.developer-tech.com/news/zscaler-security-trends-challenging-developers/#respond Tue, 15 Oct 2024 15:28:37 +0000 https://www.developer-tech.com/?p=46694 Zscaler has released its annual ThreatLabz report, highlighting security challenges that should be on every developer’s radar. The 2024 Mobile, IoT, and OT Threat Report – covering June 2023 to May 2024 – highlights critical vulnerabilities in mobile applications, IoT devices, and operational technology (OT) systems that demand immediate attention from the development community. One... Read more »

The post Zscaler highlights security trends challenging developers appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/zscaler-security-trends-challenging-developers/feed/ 0
Entry points threaten multiple open-source ecosystems https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/ https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/#respond Mon, 14 Oct 2024 13:58:48 +0000 https://www.developer-tech.com/?p=46680 While current tools have improved at detecting common tactics for exploiting open-source packages, a feature remains largely overlooked: entry points. Security researchers at Checkmarx uncovered how attackers can leverage entry points across multiple programming ecosystems, with a particular focus on PyPI, to trick victims into running malicious code. This method – while not allowing for... Read more »

The post Entry points threaten multiple open-source ecosystems appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/feed/ 0
GitLab releases critical security patches amid vulnerability streak https://www.developer-tech.com/news/gitlab-releases-critical-security-patches-vulnerability-streak/ https://www.developer-tech.com/news/gitlab-releases-critical-security-patches-vulnerability-streak/#respond Fri, 11 Oct 2024 13:30:48 +0000 https://www.developer-tech.com/?p=46671 GitLab has released a new round of critical security patches for its Community Edition (CE) and Enterprise Edition (EE) products. The company strongly recommends that all self-managed GitLab installations be upgraded immediately to one of the latest versions: 17.4.2, 17.3.5, or 17.2.9. These patch releases address several critical and high-severity vulnerabilities, including a critical flaw... Read more »

The post GitLab releases critical security patches amid vulnerability streak appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/gitlab-releases-critical-security-patches-vulnerability-streak/feed/ 0
Safe Coding: Google’s strategy reduces memory safety vulnerabilities https://www.developer-tech.com/news/safe-coding-google-strategy-reduces-memory-safety-vulnerabilities/ https://www.developer-tech.com/news/safe-coding-google-strategy-reduces-memory-safety-vulnerabilities/#respond Thu, 26 Sep 2024 14:10:17 +0000 https://www.developer-tech.com/?p=46617 Google has unveiled compelling data highlighting the efficacy of its “Safe Coding” approach in reducing memory safety vulnerabilities. The tech giant’s strategy, which prioritises the use of memory-safe programming languages for new code development, has yielded impressive results. Most notably, Android has seen a sharp decline in memory safety vulnerabilities, plummeting from 76% of all... Read more »

The post Safe Coding: Google’s strategy reduces memory safety vulnerabilities appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/safe-coding-google-strategy-reduces-memory-safety-vulnerabilities/feed/ 0
North Korean hackers target developers with fake job interviews https://www.developer-tech.com/news/north-korean-hackers-target-developers-fake-job-interviews/ https://www.developer-tech.com/news/north-korean-hackers-target-developers-fake-job-interviews/#respond Wed, 11 Sep 2024 16:11:25 +0000 https://www.developer-tech.com/?p=46518 Cybersecurity researchers at ReversingLabs have uncovered malicious software packages linked to a campaign known as VMConnect, believed to be orchestrated by the North Korean hacking team Lazarus Group. The campaign, first identified in August 2023, uses fake job interviews to lure developers into downloading and executing malicious code. The latest samples were traced to GitHub... Read more »

The post North Korean hackers target developers with fake job interviews appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/north-korean-hackers-target-developers-fake-job-interviews/feed/ 0